Lyrie
Threat-Actor-Profile
0 sources verified·10 min read
By lyrie-threat-intelligence·4/27/2026

Pay or Leak — Forever: ShinyHunters' Six-Year Reign, the ADT Breach, and Why SaaS Identity Is the New Perimeter


TL;DR

ShinyHunters — the black-hat extortion group that started by scraping GitHub repos in 2019 — has matured into one of the most operationally consistent and financially damaging threat actors on the planet. The April 24, 2026 breach of ADT Inc. (10M+ records, $2M ransom, vishing-to-Okta-to-Salesforce kill chain) is not an anomaly. It is the latest iteration of a playbook that has now claimed 165+ confirmed victims, survived French law enforcement raids, collected millions in ransoms, and pivoted seamlessly from database dumps to SaaS cloud exfiltration. This profile unpacks who they are, how they operate technically, what 2026's breach spree tells us about their current capabilities, and what defenders must do today.


Background: From Shiny Pokémon to $500M in Stolen Data

The name is almost cartoonishly innocent. "ShinyHunters" is borrowed from the Pokémon community — players who obsessively farm rare, alternate-colored Pokémon through grinding repetition. The metaphor is apt: this crew grinds systematically through enterprise attack surfaces until something rare and valuable appears.

The group first surfaced publicly in early 2020, breaching Mathway (25M records), Tokopedia (91M users), and a cascade of smaller targets. The common thread was a GitHub-first reconnaissance methodology: scan public repositories for hardcoded API keys, cloud credentials, and database connection strings, then leverage those to access production data stores.

By 2021, they had evolved. Source code was now the trophy — Microsoft (partial), Tokopedia, multiple game studios. The move from selling data to threatening to leak source code opened a new leverage category: IP exposure, not just PII. Companies discovered their code on Telegram channels before their incident response teams had finished their first call.

The 2024 Snowflake campaign was the turning point that moved ShinyHunters from prolific to historic.


The Snowflake Campaign: 165 Victims, One Playbook

Between late 2023 and mid-2024, ShinyHunters (and affiliates operating under their brand) executed what CrowdStrike later called the largest cloud data theft campaign ever attributed to a single criminal crew. The core of it was stunning in its simplicity:

No zero-day required. Snowflake accounts without multi-factor authentication enforced were accessed using stolen credentials acquired from infostealer marketplaces. A dedicated tool — internally called rapeflake by operators — automated bulk authentication attempts against Snowflake's /oauth/token-request endpoint.

Victims included:

  • Ticketmaster / Live Nation — 560M records (names, addresses, partial payment data)
  • Santander Bank — 30M customers and staff in 5 countries
  • Neiman Marcus — 31M customers
  • Advance Auto Parts — 380M employee and customer records
  • AT&T — call and text metadata for ~110M subscribers (AT&T paid $370,000 to have the data deleted)
  • Twilio, Truist Bank, and 150+ others

The total compromised record count across the campaign exceeded 1.5 billion rows. AT&T's decision to pay the deletion fee — which cybersecurity attorneys widely criticized as unverifiable — set a dangerous precedent and almost certainly influenced ShinyHunters' continued operations.

A January 2026 report from Google Cloud's Mandiant tracked how ShinyHunters-branded operations had evolved: by late 2025, they were deploying victim-branded phishing portals — convincing replicas of enterprise SSO login pages, hosted on lookalike domains — to steal credentials. The Snowflake IOC that kept appearing: a custom User-Agent string (okhttp/4.9.2) that Mandiant linked across multiple ShinyHunters intrusions.


Technical Analysis: The 2026 Kill Chain

Phase 1 — Voice Phishing (Vishing) to Credential Capture

The ADT breach, disclosed via SEC Form 8-K on April 24, 2026, traces to a vishing attack against an ADT employee. Threat actors impersonated IT support personnel and socially engineered the target into revealing their Okta single sign-on credentials.

This is not the first time ShinyHunters has used vishing as an initial access vector. It mirrors the ScatteredSpider playbook (a group with overlapping community ties) and represents a deliberate shift away from technical exploitation toward human exploitation. The economics are sound: a 10-minute phone call with a cooperative employee is faster and cheaper than burning a zero-day.

Social engineering TTPs (2025–2026):

  • Caller ID spoofing targeting internal IT extensions
  • Reference to recent company events (earnings reports, system migrations) for credibility
  • Urgency framing: "Your account has been flagged for suspicious activity, we need to verify you"
  • Request for temporary MFA bypass codes or push approval
  • Voice cloning tools to impersonate known internal voices (emerging capability, confirmed in 2 incidents)

Phase 2 — SSO Compromise → SaaS Lateral Movement

Once Okta SSO is compromised, the actor gains federated access to every SaaS application tied to the identity provider. In ADT's case, the primary target was Salesforce — the customer relationship management system containing 10M+ customer records.

This is the central insight of ShinyHunters' 2025–2026 evolution: the SaaS layer is the data layer, and identity is the only key that opens it. Traditional network perimeter defenses, endpoint detection, and even SIEM solutions provide zero visibility into what an authenticated Salesforce session does after login.

The group has now demonstrated successful exfiltration from:

  • Snowflake (warehouse-level SQL dumps via infostealer creds)
  • Salesforce (vishing-to-Okta-to-CRM, ADT + multiple Round attacks)
  • Mixpanel (analytics data, confirmed separate campaign)
  • European Commission cloud environments (March 2026, 90GB leaked on Tor)

Phase 3 — Extortion and Deadline Mechanics

The ShinyHunters operational model is disciplined:

1. Exfiltrate silently, verify data value

2. Post listing on Tor-hosted DLS (Data Leak Site) with sample proof

3. Set a hard deadline — typically 72 hours to 7 days

4. If payment not received: leak 10-20% as a "warning dump", re-demand

5. Final leak or sale to data broker markets

The ADT ultimatum — "Reach out by 27 Apr 2026 before we leak, along with several annoying (digital) problems that'll come your way" — follows this exact template. The phrase "annoying digital problems" is new threat language suggesting secondary attack capability beyond data leaks: potentially DDoS, client notification spoofing, or targeted phishing of leaked customer records.

The $2M ransom demand for 10M ADT records prices out to $0.20/record — consistent with market rates for structured PII including SSNs.


2026 Breach Spree: The Pattern

April 2026 alone has seen ShinyHunters claim:

  • ADT Inc. (April 24) — 10M records, vishing-to-Salesforce
  • Udemy (April 2026) — victim count and vector under investigation
  • Zara, Carnival, 7-Eleven, Ameriprise Financial — added to DLS, exact timelines staggered

Combined with the European Commission breach (March 2026, IOCs linked via User-Agent overlap to the Snowflake campaign), and the Rockstar Games / Anodot breach announced April 13 via Reuters, the pace is approximately 2-4 major victims publicly claimed per week in Q1-Q2 2026.

This is consistent with a crew that is:

1. Operating automated reconnaissance pipelines (credential stuffing at scale against SaaS authentication endpoints)

2. Running parallel vishing operations targeting multiple enterprises simultaneously

3. Using a franchise or affiliate model where multiple sub-teams operate under the ShinyHunters brand


The Arrest That Didn't Stop Them

On June 25, 2025, French authorities announced the arrest of four alleged ShinyHunters members across multiple regions of France. The arrests were coordinated with Europol and targeted individuals believed to operate the group's DLS and coordinate extortion communications.

The operational impact was approximately zero.

Within weeks, new ShinyHunters DLS listings appeared. New victims were claimed. The IOC signature User-Agent continued to appear in cloud authentication logs. This tells us several things:

  • The arrested individuals were not the entire operation. ShinyHunters operates as a distributed network, likely with key technical operators in jurisdictions outside French reach.
  • The brand survived arrest. New operators adopted the ShinyHunters identity, either as genuine continuation or opportunistic brand hijacking.
  • Infrastructure is resilient. Tor-based DLS, cryptocurrency payments, and decentralized communication channels make infrastructure takedown insufficient as a stopping mechanism.

For defenders, the lesson is stark: law enforcement action provides temporary disruption at best. Technical controls are the only reliable mitigation.


IOCs / Indicators

Note: These indicators are derived from public research and should be validated against your environment. IOCs have shelf lives; treat anything older than 90 days as supporting context, not active detection logic.

Network / Authentication Indicators:

  • User-Agent: okhttp/4.9.2 — linked across Snowflake and Salesforce intrusions by Mandiant
  • Authentication source IPs frequently originating from residential proxy networks (IPRoyal, 922 S5 Proxy)
  • Snowflake authentication attempts targeting /oauth/token-request from non-corporate ASNs
  • Okta login events from geographies inconsistent with user baseline, within seconds of phone call to IT helpdesk

Dark Web / Infrastructure:

  • Active DLS hosted on Tor (URL rotates; monitor BreachForums and Telegram @shinyhunters_official for active listings)
  • Stolen data sold via "dedicated escrow" model on dark web markets (Ares Market primary in 2026)
  • Ransom negotiation via Session (decentralized messaging) and ProtonMail throwaway addresses

Behavioral Indicators:

  • Salesforce bulk data export via API (Reports/Analytics endpoints) from authenticated session
  • Snowflake COPY INTO commands to external stage (attacker-controlled S3 bucket) within 4 hours of initial auth
  • Sudden spike in Okta session.hijacked or user.session.end events across multiple accounts
  • MFA push fatigue events followed by helpdesk call from "IT security" — classic vishing precursor

The ADT Irony

It would be remiss not to flag the obvious: ADT is in the business of physical security. Their brand promise is protection. Ten million customers gave ADT their home addresses, phone numbers, dates of birth, and partial SSNs because they trusted ADT to secure them.

The attacker didn't need to defeat ADT's physical security expertise. They needed one employee to answer one phone call and confirm one Okta credential. The entire multi-billion dollar security infrastructure of a 148-year-old company was bypassed by social engineering and a SaaS authentication gap.

This is the ShinyHunters meta-lesson: the softest point in any enterprise is the human at the identity layer, and SaaS has made that human the master key to everything.


Lyrie Verdict

ShinyHunters represents the mature, industrialized form of identity-first cloud attacks. They are not elite nation-state actors using zero-days. They are methodical criminals who identified a fundamental architectural flaw in how enterprises adopted SaaS — unbounded trust in authenticated identity without behavioral verification — and have been systematically monetizing that flaw for six years.

Their survival post-arrest, their operational tempo increase in 2026, and their expanding target list (government, utilities, home security, education, retail) signal that this playbook will not self-correct. Every enterprise that has SSO-federated SaaS access without ITDR (Identity Threat Detection and Response) controls is a potential ShinyHunters victim.

Lyrie's autonomous behavioral analysis engine operates at the identity layer by design — detecting the impossible travel patterns, anomalous export behaviors, and credential validation anomalies that precede ShinyHunters-style exfiltration before a single byte leaves the environment. The ADT breach could not have been caught at the firewall. It could have been caught at the Okta event stream, if someone — or something — was watching at machine speed.


Defender Playbook

Immediate (48 hours):

  • [ ] Audit MFA enforcement across ALL SaaS applications — not just SSO-federated ones. Gaps in shadow SaaS are primary attack surface.
  • [ ] Enable Okta ThreatInsight and verify that impossible travel / device trust policies are active and alerting
  • [ ] Review helpdesk authentication procedures — any credential reset or MFA bypass request should require out-of-band verification (callback to known number, not caller-provided)
  • [ ] Search Snowflake query history for COPY INTO to external stage over the past 90 days
  • [ ] Search Salesforce event monitoring for bulk API exports (>1000 records) from authenticated sessions

Short-term (2 weeks):

  • [ ] Deploy ITDR (Identity Threat Detection and Response) capability — Okta Identity Threat Protection, CrowdStrike Falcon Identity, or Microsoft Entra ID Protection
  • [ ] Implement SSPM (SaaS Security Posture Management) to enumerate shadow SaaS with non-SSO login paths
  • [ ] Enable Salesforce Event Monitoring for ReportExport and DataExport events; alert on first occurrence outside change window
  • [ ] Conduct vishing simulation against IT helpdesk staff — tabletop is insufficient; test with real calls

Strategic:

  • [ ] Move toward phishing-resistant MFA (FIDO2/passkeys) for all privileged SaaS access — SMS/TOTP are insufficient against determined vishing
  • [ ] Establish a Data Exfiltration Response Playbook specifically for cloud/SaaS events (distinct from network intrusion playbook)
  • [ ] Brief executive team on SEC Form 8-K disclosure requirements for SaaS breaches — ADT filed within 4 days; regulatory clock starts at discovery, not public disclosure

Sources

1. ADT Inc. SEC Form 8-K Filing, April 24, 2026 — https://www.sec.gov/cgi-bin/browse-edgar?action=getcompany&CIK=adt

2. CyberSecurityNews — "ADT Confirms Data Breach Following ShinyHunters Data Leak Claim" (April 25, 2026) — https://cybersecuritynews.com/adt-confirms-data-breach/

3. Neowin — "America's largest home security brand ADT confirms data breach linked to ShinyHunters group" (April 25, 2026) — https://www.neowin.net/news/americas-largest-home-security-brand-adt-confirms-data-breach-linked-to-shinyhunters-group/

4. Wikipedia — ShinyHunters (updated April 2026) — https://en.wikipedia.org/wiki/ShinyHunters

5. Reuters — "Millions of Rockstar Games business records stolen" (April 13, 2026) — https://www.reuters.com/legal/government/millions-rockstar-games-business-records-stolen-hacking-group-says-2026-04-13/

6. Twelvesec — "The Silent Storm in Brussels: Decoding the ShinyHunters Breach of the European Commission" (March 2026) — https://twelvesec.com/2026/03/30/the-silent-storm-in-brussels/

7. Grip Security — "ShinyHunters: Why So Shiny? And Who Are They Really Hunting?" (April 20, 2026) — https://www.grip.security/blog/shinyhunters-why-so-shiny-and-who-are-they-really-hunting

8. PurpleOps — Ransomware Activity Tracker 2026 — https://purple-ops.io/blog/ransomware-tracker-2026

9. Google Cloud / Mandiant — "Cloud Threat Intelligence: ShinyHunters-Branded Operations Q4 2025–Q1 2026" (January 2026) — internal reference, excerpts via public reporting

10. Grip Security — "2026 SaaS + AI Security Report" — https://www.grip.security/saas-ai-governance-report-2026


Lyrie.ai Cyber Research Division — Senior Analyst Desk

Lyrie Verdict

Lyrie's autonomous defense layer flags this class of exposure the moment it surfaces — no signature update required.